criticalOther

Hitachi Energy FACTS Control Platform (FCP) Multiple Vulnerabilities

First seen Sep 18, 2026 · Updated Sep 18, 2026 · CVSS 9.9

ICSOTcritical-infrastructureenergy-sectorhitachi-energypath-traversalauthentication-bypasssession-hijackingopen-redirectCISA-advisory

Hitachi Energy's FACTS Control Platform (FCP) with the GWS component is affected by five vulnerabilities, including a critical query injection flaw (CVSS 9.9) and a critical path traversal flaw (CVSS 9.9), along with authentication bypass, missing authentication, and open redirect issues. These affect FACTS-based grid stabilization equipment (SVC Light, STATCOM, series capacitors, synchronous condensers) deployed globally in the energy sector since 2020, and successful exploitation could compromise confidentiality, integrity, and availability of critical power grid control systems.

Technical Analysis

The advisory details five CVEs affecting Hitachi Energy FCP versions 3.4.0 through 4.1.1 when the GWS component is present: CVE-2024-4872 (CWE-943, CVSS 9.9) allows an authenticated attacker to inject code into persistent data via improper query validation; CVE-2024-3980 (CWE-22, CVSS 9.9) is a path traversal flaw enabling access/modification of critical system files; CVE-2024-3982 (CWE-294, CVSS 8.2) permits session hijacking via replay when session logging is enabled; CVE-2024-7940 (CWE-306, CVSS 8.3) exposes a service intended for local-only access to all network interfaces without authentication; and CVE-2024-7941 (CWE-601, CVSS 4.3) enables open-redirect-based phishing and credential theft. These vulnerabilities target OT/ICS equipment used in power grid stabilization (SVC Light, STATCOM, TCSC, SVC, SWC, hybrid synchronous condensers) and require network segmentation, firewalling, and VPN-based remote access as primary mitigations since no patch details are specified beyond general mitigation guidance. This is a pure OT/ICS vulnerability set with no direct connection to AI agent frameworks, LLM tool use, or RAG pipelines, and thus no plausible agent-relevant impact is present.

Affected Systems

Hitachi Energy FACTS Control Platform (FCP) versions 3.4.0, 3.7.0, 3.8.0, 3.10.0, 3.12.0, 3.14.0, 3.15.0, 4.0.0, 4.0.1, 4.1.0, 4.1.1 with GWS component deployed from 2020 onwards; product lines include SVC Light (STATCOM), Fixed Series Capacitor, Thyristor Controlled Series Capacitor, Static Var Compensator, Static Watt Compensator, and Hybrid Synchronous Condensers. Deployments without the GWS component are not affected.

Indicators of Compromise

  • No specific indicators of compromise (hashes, IPs, domains) provided in this advisory; this is a vulnerability disclosure rather than an active exploitation report.

Remediation Steps

  1. 1

    Apply vendor guidance

    Consult Hitachi Energy security advisory 8DBD000229 for specific mitigation and remediation details applicable to each CVE.

  2. 2

    Network segmentation

    Isolate control system networks and remote devices behind firewalls, separating them from business networks and the internet.

  3. 3

    Minimize exposure

    Ensure control system devices, especially those with the GWS component, are not accessible from the internet and minimize the number of exposed network ports/services.

  4. 4

    Secure remote access

    Use VPNs for remote access where required, ensuring VPN software is kept up to date and endpoint devices are secured.

  5. 5

    Restrict session logging

    Keep session logging disabled by default and restrict administrator rights to prevent session hijacking via CVE-2024-3982.

  6. 6

    Credential hygiene

    Enforce strong password policies and monitor for authentication bypass attempts given CVE-2024-3982 and CVE-2024-7940.

  7. 7

    Monitor and report

    Follow internal incident response procedures and report suspected malicious activity to CISA for correlation with other incidents.

CVE / Advisory IDs

CVE-2024-4872CVE-2024-3980CVE-2024-3982CVE-2024-7940CVE-2024-7941

Industries Most Exposed

EnergyCritical InfrastructureUtilities

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.